Executive brief
Miraikan Assist App is a mobile application used to enhance visitors' experience at the Miraikan museum. A cross-site scripting vulnerability in the app's WebView component allows an attacker to execute arbitrary scripts, potentially altering displayed content and deceiving users. The vulnerability requires user interaction and affects both iOS and Android versions prior to patched releases.
Technical details
This cross-site scripting (CWE-79) vulnerability exists in the WebView component of Miraikan Assist App. The vulnerability requires network accessibility and user interaction to exploit; an attacker can craft malicious input that, when processed by the WebView, executes arbitrary JavaScript code in the security context of the application. The impact is limited to display manipulation (script execution does not gain code execution on the host OS or access to sensitive data outside the WebView context). Patches are available: Android version 1.1.7 and later, and iOS version 1.0.7 and later have addressed this issue.
Affected products
- Japan Science and Technology Agency Miraikan Assist App Android prior to 1.1.7
- Japan Science and Technology Agency Miraikan Assist App iOS prior to 1.0.7
Timeline
- 2026-08-21: disclosed
- 2026-08-19: patched: Update released for both Android (1.1.7+) and iOS (1.0.7+) versions